For UK SMBs · public

UK supplier due diligence, without the false confidence.

UK buyers routinely ask suppliers for ISO 27001, Cyber Essentials, and UK GDPR / Data Protection Act 2018 evidence. Keepgrade gives UK small and midsize organisations a continuous AI readiness copilot between formal engagements — a 15-minute readiness score across the framework mix, the per-domain gap map, and the assessor routing when you are ready to certify or attest.

ISO 27001 supplier asks

Major UK buyers — finance, healthcare, critical infrastructure — request ISO 27001 evidence or a credible readiness narrative. The certificate is issued by an accredited certification body; a self-attested readiness score cannot grant it.

Cyber Essentials for public-sector suppliers

Government and NHS-linked procurements frequently require Cyber Essentials or Cyber Essentials Plus. The scheme is administered by IASME on behalf of NCSC; readiness scoring supports the application, but does not issue the badge.

UK GDPR / DPA 2018 evidence asks

Buyers and Data Protection Officers request Article 30 records of processing, DPIAs, and breach-notification evidence. UK GDPR is a regulatory floor enforced by the ICO, not a certifiable framework — readiness scoring surfaces where the evidence gaps are.

Common UK frameworks — explained honestly
Each framework below has a different kind of authority behind it. A readiness score is useful for every one, but it is not any of the certificates, badges, or attestations themselves.
  • ISO 27001:2022

    Certification

    The certificate is issued by an accredited certification body after a Stage 1 (readiness review) and Stage 2 (on-site audit) process. Keepgrade's readiness score is the self-attested groundwork that prepares you for the audit — never the certificate itself.

  • Cyber Essentials

    Voluntary scheme (NCSC-aligned)

    Administered by IASME on behalf of the National Cyber Security Centre. Basic and Plus tiers differ in the verification model (self-answered questionnaire vs hands-on technical audit). Readiness scoring supports the application and surfaces what would fail the Plus technical check.

  • UK GDPR / Data Protection Act 2018

    Regulatory framework (ICO)

    A regulatory floor enforced by the Information Commissioner's Office, not a certifiable framework. Readiness scoring surfaces Article 30 records of processing, DPIA coverage, and breach-notification readiness gaps against the regulation.

How Keepgrade fits the UK journey
A short, honest sequence that maps readiness scoring into the existing UK engagement mix — without overpromising what 'ready' means for any one framework.
  1. Stage 1

    Run a 15-minute readiness score

    Pick ISO 27001 or SOC 2 from the framework picker, answer the same twelve NIST-CSF-functions-tagged questions, and leave with a per-domain 0..100 score and band. The instrument is the same one our deeper engagements are grounded against.

  2. Stage 2

    Review the per-domain gap map

    See exactly where ISO/CE/UK-GDPR evidence asks are uncovered — Annex A control families, the NCSC Cyber Essentials technical themes, or Article 30 / DPIA evidence gaps. The next 30 minutes of hardening effort is obvious from the gap map.

  3. Stage 3

    Route to the right UK-aligned assessor

    When the band is ready, the assessor marketplace routes you to a UK-appropriate assessor type — accredited ISO certification bodies, Cyber Essentials certification bodies, ICO-ready UK DPOs, or AICPA SOC auditors for transatlantic SaaS.

What a readiness score is (and isn't)
Honest framing before you commit to the questionnaire — the same disclaimers that appear on every framework result panel.

A readiness score is a self-attested readiness number against a published control set. The number answers one question: how ready is the org to pass the authoritative audit / attestation / assessment for this framework? We compute the number once on every submission using a deterministic + AI-validated scoring engine, then surface it with a band and a per-domain gap map so the next 30 minutes of hardening effort is obvious.

For UK journey buyers, that distinction matters: a readiness score of 78 against ISO 27001 tells you you are ready to commission a Stage 1 + Stage 2 audit — the certificate itself is still issued by an accredited certification body. A readiness score of 0..100 against UK GDPR tells you which Article 30 records and DPIAs are missing — it does not demonstrate compliance to the ICO.

Run a readiness score before the next buyer questionnaire lands.

Fifteen minutes, no signup, a per-domain score and band against ISO 27001 or SOC 2 — and a clear next move when the band is ready. See plans and bespoke Remix engagements in pricing.